David Leigh publishes Cablegate password in his book
nigelparry.com
nigelparry.com
It's the fault of Wikileaks for releasing a copy of this file in to the wild, and for (as might be implied by the article linked to) using the same passwords repeatedly.
As the events demonstrate, it is extremely unwise to take such an over-the-top unnecessary risk with such a critical password.
The failure here is that Wilileaks used a single password to protect a file that was distributed to multiple parties, meaning that multiple people had to maintain a shared secret.
I don't know how you'd time limit the password itself. It isn't as if I could send you an encrypted file, with a key that will only decrypt that file for that day.
Even if Assange had made absolutely sure to destroy any copy he had of the file which used that key (which would have been a Good Idea), he could not guarantee that some router on the internet didn't store a copy of the entire download session.
Regardless of how the blame is distributed, the decision to publish such a sensitive password in such a public manner still stands out to me as the most boneheaded single action in the entire saga.
Assange didn't want to give them access to the cables at all, but relented when they demanded it in negotiations with him. He then made them sign a contract to protect the information [1]. Clearly this wasn't enough though.
[1] http://wikileaks.org/IMG/pdf/Guardian_Letter_for_Package_3.p...